GPEN › Escalation and Exploitation
This GPEN domain covers turning limited access into root or SYSTEM: kernel exploits, Windows privilege abuse, and service misconfigurations. Questions are scenario-based, asking you to pick the correct escalation path, tool, or built-in Windows feature, and to recognize why an action is risky or destructive during a sanctioned penetration test.
GPEN Escalation and Exploitation — All 31 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Advanced Password Attacks
Pen Test Planning